Ubunifu InstituteEffective / reviewed: 4 September 2026Applies to the public website and relevant digitally supported relationships
01
Scope and responsibility
This policy applies to personal data processed by or for Ubunifu Institute through the public website, applications, learning and programme journeys, events, Network relationships, Emporium, research, support and related communications.
The specific legal entity, contract, partner or programme responsible for a relationship remains distinct. A technology or delivery partner does not automatically become the controller of Ubunifu programme data.
02
Personal data we may collect
- Identity and contact data, including First Name, optional Middle/Family Name, Last Name/Surname, email, phone and country/location details.
- Application, learning, assessment, attendance, mentoring, venture and programme-progress records.
- Organization, partner, supplier, buyer, seller, researcher and professional relationship information.
- Emporium, transaction, payment-reference, delivery and support records where a transaction is available and actually used.
- Research, consent, ethics, access, publication and evidence records where relevant.
- Technical and security records such as session, device, log, fraud-prevention and audit information.
- Communications, preferences, enquiries, complaints and evidence needed to resolve a request.
03
Why we process data
Ubunifu processes personal data only for defined purposes connected to learning, programme administration, enterprise development, market access, research, events, support, relationship management, security, legal obligations and institutional governance.
- To provide a requested service or take steps connected to a programme or contract.
- To manage consent-based communications or optional public profiles where consent or approval is the appropriate basis.
- To comply with legal, tax, accounting, safeguarding, security or regulatory obligations.
- To pursue legitimate institutional purposes where those interests are lawful, necessary and balanced against the rights of the person concerned.
04
Public profiles and publication controls
Private programme records do not become public merely because a person, venture or organization participates in Ubunifu. Public profiles are limited to fields approved for publication. Draft Business Plans, private contact details, assessment notes, ownership information, financial records, contracts and protected research evidence remain outside ordinary public pages unless a lawful, explicit publication basis exists.
05
Sensitive data, children and safeguarding
Ubunifu minimises collection of sensitive personal data and collects it only where a valid purpose and lawful basis exist. Journeys involving children, vulnerable people or safeguarding concerns require additional controls, appropriate authority/consent and restricted access. Public forms should not be used to submit unnecessary sensitive information.
06
Sharing, processors and partners
Data may be shared with authorised staff, contracted processors, payment/communications providers, professional advisers, delivery partners or authorities only to the extent required for a defined purpose and subject to applicable safeguards. Strategic partners remain separate legal entities; access is scoped rather than assumed.
07
International transfers and cloud services
Where personal data is stored, accessed or processed outside Kenya through approved cloud, communications or other providers, Ubunifu applies the transfer safeguards required by applicable data-protection law and the relevant approved contracts/configuration. A provider being technically available is not the same as a production connector being authorised.
08
Retention and disposal
Records are retained only for as long as needed for the purpose for which they were collected and for applicable legal, finance, tax, contractual, safeguarding, dispute, security, research or audit requirements. When a record no longer needs to identify a person, it may be deleted, anonymised or securely disposed of according to the applicable retention decision.
09
Security and access
Ubunifu uses role- and purpose-based access, protected system surfaces, audit trails and other technical/organisational controls. No online service can be promised to be risk-free; security incidents are handled through governed detection, containment, investigation, notification and recovery processes as applicable.
10
Your data-protection rights
A request may require reasonable identity verification so that one person cannot access, alter or delete another person’s records.
- Be informed about use of your personal data.
- Request access to personal data held about you.
- Request correction of inaccurate or misleading data.
- Object to processing where the law gives that right.
- Request erasure or deletion where the applicable conditions are met.
- Request restriction of processing in appropriate circumstances.
- Request data portability where applicable.
11
Questions, complaints and policy changes
Use the Contact page for a privacy request or concern. Ubunifu will record and route the request to the accountable function. You may also exercise rights or make a complaint through the Office of the Data Protection Commissioner where applicable. This policy may be updated when law, systems, programmes or processing purposes change.
Official referencesRegulatory sources
These links are provided for current authoritative context. Where a policy conflicts with applicable law, the law and a formally approved instrument govern.